Uploaded image for project: 'Oozie'
  1. Oozie
  2. OOZIE-2538

Update HttpClient versions to close security vulnerabilities

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 4.3.0
    • core
    • None

    Description

      We learned that

      https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5262 : http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.

      Also, Commons HttpClient project is now end of life, and is no longer being developed. It has been replaced by the Apache HttpComponents project in its HttpClient and HttpCore modules, which offer better performance and more flexibility. http://hc.apache.org/httpclient-3.x/

      Hence, HttpClient version should be updated.

      Attachments

        1. OOZIE-2538.patch
          4 kB
          Abhishek Bafna
        2. OOZIE-2538-01.patch
          5 kB
          Abhishek Bafna
        3. OOZIE-2538-02.patch
          4 kB
          Abhishek Bafna
        4. OOZIE-2538-03.patch
          5 kB
          Abhishek Bafna

        Issue Links

          Activity

            People

              abhishekbafna Abhishek Bafna
              abhishekbafna Abhishek Bafna
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: